gherkin-ticket

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes ticket titles, descriptions, and comments fetched from the Linear platform, which serves as an untrusted data source.\n
  • Ingestion points: Ticket data is retrieved through the linear_read_ticket function in scripts/lib/linear-read-replica.sh and the linearis CLI tool as described in the SKILL.md rewrite instructions.\n
  • Boundary markers: The instructions do not specify the use of delimiters or clear directives to the agent to ignore potentially malicious instructions embedded within the ticket data.\n
  • Capability inventory: The skill possesses the ability to modify project files and update tickets using the Write, Edit, and linearis tools.\n
  • Sanitization: There is no evidence of content sanitization or filtering applied to the ingested ticket data before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:29 PM
Security Audit — agent-trust-hub — gherkin-ticket